Three US agencies told AI firms to quietly degrade China’s access, not block it

The advice is not to shut suspected accounts down but to feed them slightly worse answers, and nothing makes anyone follow it.

Abstract EMRGNG cover image for a story about DeepSeek

Six Chinese AI companies were named on 8 September in a joint advisory from CISA, the NSA and the FBI. It accused DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI of running industrial-scale distillation against American frontier models, pulling billions of tokens across millions of requests since late 2024 from Anthropic’s Claude, OpenAI’s GPT, Google’s Gemini and xAI’s Grok. Distillation on this scale, the advisory said, is the core of China’s AI strategy, not a supplement to it.

Distillation means training a cheaper model on a stronger one’s outputs. The advisory says the companies used fraudulent accounts, bulk premium subscriptions and proxy routing services it calls transfer stations to get past usage limits and regional blocks. It singles out DeepSeek, whose widely cited 5.6 million dollar training cost it calls misleading for leaving out the data acquired through distillation. Nick Andersen, CISA’s acting director, urged AI companies to act at once to protect their platforms.

The recommended response is the unusual part. Rather than banning accounts flagged with high confidence, the agencies suggest providers subtly weaken the answers those accounts receive, cutting reasoning depth or routing correct information through worse explanations, so the copying is less useful without tipping off the copier. They also want model providers, cloud platforms and API resellers to pool their detection data.

The advisory carries no new legal authority. Distilling a rival’s model breaches terms of service but is not a crime, no sanctions came with the warning, and the companies named have previously denied training on competitors’ output. The agencies did not say how many tokens amount to a working copy, or how a provider proves distillation rather than ordinary heavy use before handing a paying customer degraded answers.

Read more here.

More from EMRGNG